Laws · GDPR ·art-83-par-3 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.
How it connects
Cited by
- DeFine is a calculator for GDPR fines based on method of the EDPB
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- UODO fines accounting firm €2,760 for email breach security failures
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
All 24
- UODO (Poland) - DKN.5131.27.2023
- Garante per la protezione dei dati personali (Italy) - 10192784
- Statement 2/2024 on the financial data access and payments package
- EDPB-EDPS Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse
- EDPB Annual Report 2021
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Austrian court reviews postal service selling political affinity data of customers
- UODO (Poland) - DKN.5131.5.2025
- DSB (Austria) - 2025-1.049.138
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on
- Garante per la protezione dei dati personali (Italy) - 551/2026
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security
- Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR